oauth-wg / oauth-cross-device-security

Other
10 stars 8 forks source link

Highlight edge cases of geolocation based on IP Address #123

Closed PieterKas closed 2 months ago

PieterKas commented 2 months ago

Add guidance on potential edge cases for implementors to be aware off when using network address as a proximity measure.

  1. In the case of 6.1.1 establishing proximity, there is a boundary (pun not intended) case where a device will shift between two different cellular providers. The IETF's Drone effort were examining the same problem as the drone flies close to an international boundary and flips back and forth to roaming and not. How to deal with this case or whether it is dependable is a question. I know that Pieter is suggesting Fido2, but the way this section is written a Consumption device may be on a weak Wifi and the authentication device has shifted to Cellular.

https://mailarchive.ietf.org/arch/msg/oauth/wC0iOyc9bPxcvv8OmnAt0EcKw6I/